Sauron Loader Chunked Screenshot Exfiltration via keyroll Process
Detects the exfiltration behavior of the Sauron Loader, where a process tree associated with rnpkeys.exe or its modules (rnp.dll, tdwp.dll) within the C:\ProgramData\keyroll directory performs a burst of numerous small HTTPS POST requests to a single destination. This pattern is characteristic of a screenshot image being fragmented into small chunks and exfiltrated.
CQL

